DigitalPulse is Windows proxyware abused in proxyjacking operations to relay traffic through compromised hosts and monetize victims’ Internet bandwidth without consent. It has been deployed by the financially motivated Larva-25012 threat actor, including campaigns that predominantly targeted systems in South Korea. Observed deployment chains use DPLoader to install and execute DigitalPulse after initial compromise through malvertising, deceptive download pages, and trojanized software installers targeting users seeking cracked software. DigitalPulse deployments establish scheduled-task persistence, use obfuscation, attempt to impair Microsoft Defender, and inject an obfuscated Go-based payload into the Windows Explorer process. The malware has also appeared in proxyjacking campaigns delivered through freeware-download advertising redirects and disguised installer programs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DigitalPulse est installé sous %SystemRoot%\pluton\<RANDOM>\plutonagent.exe avec une tâche PlutonAgentScheduler; il désactive Microsoft Defender, emploie l’obfuscation et l’injection dans Explorer.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Proxyware distribué par la campagne afin de monétiser la bande passante de systèmes compromis; son installation comprend une persistance par tâche planifiée, une désactivation de Defender, de l’obfuscation et une injection de processus.
Proxyware installed through DPLoader that monetizes victim bandwidth. It uses obfuscation and Explorer-process injection techniques to evade detection.
Proxyware payload used to monetize compromised hosts by routing third-party traffic through victim networks; described as an obfuscated Go-based program injected into explorer.exe.
Proxyware agent deployed to hijack and resell victim internet bandwidth as part of a proxyjacking scheme.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.